CVE-2017-13081
Publication date 16 October 2017
Last updated 25 August 2025
Ubuntu priority
Cvss 3 Severity Score
Description
Wi-Fi Protected Access (WPA and WPA2) that supports IEEE 802.11w allows reinstallation of the Integrity Group Temporal Key (IGTK) during the group key handshake, allowing an attacker within radio range to spoof frames from access points to clients.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| linux-firmware | ||
| 20.04 LTS focal |
Fixed 1.170
|
|
| 18.04 LTS bionic |
Fixed 1.170
|
|
| 16.04 LTS xenial |
Fixed 1.157.14
|
|
| 14.04 LTS trusty |
Fixed 1.127.24
|
|
| wpa | ||
| 20.04 LTS focal |
Fixed 2.4-0ubuntu10
|
|
| 18.04 LTS bionic |
Fixed 2.4-0ubuntu10
|
|
| 16.04 LTS xenial |
Fixed 2.4-0ubuntu6.2
|
|
| 14.04 LTS trusty |
Fixed 2.1-0ubuntu1.5
|
Notes
Severity score breakdown
CVSS version: CVSS v3.0
Base score
5.3 · Medium
Vector: CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
References
Related Ubuntu Security Notices (USN)
- USN-3505-1
- Linux firmware vulnerabilities
- 6 December 2017
- USN-3455-1
- wpa_supplicant and hostapd vulnerabilities
- 16 October 2017